Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Except that most of these appear to be served over http, sans s.


Is that an issue if nothing confidential is being served?


It’s prone to MITM attacks and it allows snooping for what pages are visited. Some US ISPs use(d) this vulnerability to inject ads into pages. On a public/shared network you might be vulnerable to automated attacks.


How long would US ISPs need to stop doing this, now that most stuff is HTTPS delivered anyways?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: